PT-2008-4215 · Dt · Dt Centrepiece
Published
2008-06-19
·
Updated
2017-08-08
·
CVE-2008-2775
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
DT Centrepiece version 4.0
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands. The issue is related to the
searchFor parameter in the "search.asp" page.Recommendations
For DT Centrepiece version 4.0, consider restricting access to the search.asp page or validating and sanitizing the
searchFor parameter to prevent SQL injection attacks. As a temporary workaround, avoid using the searchFor parameter in the search.asp page until the issue is resolved.Fix
RCE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dt Centrepiece